8Base, also tracked as 8base_ransomware_actors, is a financially motivated ransomware and extortion operation active since at least March 2022, with a pronounced increase in activity in June 2023. It conducts opportunistic attacks across multiple industries, including healthcare, food and agriculture, and manufacturing. Its victims include Japanese organizations and a manufacturing division in Vietnam. The operation uses customized Phobos ransomware and combines data theft with file encryption and threats to publish stolen information. It maintains a Tor-accessible leak site for victim naming, stolen-data publication, and ransom negotiations. The site has also published data obtained by Faust, a separate Phobos affiliate. SmokeLoader has been used to deliver 8Base ransomware, and SystemBC has been associated with its operations. Observed intrusions have involved AnyDesk deployment, LSASS credential dumping, abuse of existing user tokens, privilege escalation through runas, and PowerShell execution. Its ransomware establishes persistence through startup mechanisms and autorun registry entries, obscures executable code and imported functions, disables the Windows firewall, and inhibits recovery by deleting shadow copies and backup catalogs. Analyzed variants encrypt files using AES-256-CBC and protect encryption keys with RSA.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
25 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as one of several ransomware families tied to Woodgnat/KongTuke.
Mentioned only as one of the groups that claimed responsibility for a separate 2024 ransomware attack against another Nidec division.
Named as one of the ransomware groups publicly linked to Woodgnat as a downstream partner or affiliate receiving sold access.
Previously claimed a separate ransomware-related extortion incident involving Nidec's Vietnam-based Nidec Precision division in 2024.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.